25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

American Addiction Centers & Oculus Pathology Disclose Hacking Incidents

Hacking incidents have been announced by American Addiction Centers in Tennessee and Oculus Pathology in Texas. Regional Center of Orange County in California has discovered the improper disposal of paper records.

American Addiction Centers, Tennessee

American Addiction Centers, a Brentwood, Tennessee-based provider of addiction treatment services at more than 30 facilities across the United States, has notified the California Attorney General about a recent security incident involving a third-party vendor. According to the notice, suspicious activity was identified within its Salesforce environment on June 5, 2026.

The forensic investigation determined on June 12, 2026, that there had been unauthorized access to its Salesforce instance on May 12, 2026, and data was exfiltrated from that system. The forensic investigation confirmed that the incident did not affect any other systems. The data review confirmed that names, contact information, Social Security numbers, and health insurance information were acquired, along with brief descriptions that patients provided related to their health. The affected data related to initial outreach to American Addiction Centers.

American Addiction Centers said that security measures had been implemented prior to the breach and that it will continue to review its security measures to further protect and monitor its Salesforce environment, and complimentary credit monitoring and identity theft protection services have been made available. At present, it is unclear how many individuals have been affected.

Oculus Pathology, Texas

Oculus Pathology, an Austin, Texas-based anatomic and clinical pathology group that provides services in several U.S. states, has announced an email security incident that has exposed patient information. Suspicious activity was identified within an employee’s email account on April 1, 2026. An investigation was launched to determine the nature and scope of the activity, and it was determined that a small number of employee email accounts had been accessed by an unauthorized third party between March 31, 2026, and April 2, 2026.

Data review specialists were engaged to investigate the incident. Data exposed in the incident includes personally identifiable information such as names, birth dates, Social Security numbers, driver’s license numbers/state ID numbers, and individual tax identification numbers. Some financial account numbers and payment card numbers were exposed, in some cases with access information.

In addition, protected health information was exposed, including clinical information, health insurance information, diagnoses, treatment and procedure information, treatment locations, medical record numbers, Medicare numbers, prescription information, and patient IDs. The data review is ongoing. Oculus Pathology has yet to announce how many individuals have been affected in total.

Regional Center of Orange County, California

Regional Center of Orange County, a Santa Ana, California-based nonprofit organization that provides services to approximately 29,000 Orange County residents with autism, epilepsy, cerebral palsy, and intellectual and cognitive disabilities, has announced a data security incident that has exposed sensitive data. The incident involved paper records that were mistakenly disposed of by a Janitorial service contracted to clean its Cypress office. The incident occurred on May 27, 2026, and was discovered on May 28, 2026. Documents had been disposed of in regular trash bins rather than being sent for secure destruction. Attempts were made to retrieve the documents; however, the trash had already been collected.

It was not possible to determine the exact patients involved or the specific types of information, so notification letters have been sent to all individuals who received services at the Cypress office.  Data likely exposed included names, addresses, birth dates, phone numbers, email addresses, unique client identifiers, and personal health information. Regional Center of Orange County said it is reviewing and strengthening internal procedures, staff training, and vendor oversight to prevent similar incidents in the future, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist